CyberTRIZPEDIA

NIST SP 800-53 Rev. 5

Official NIST CSRC publication page. | Tags: NIST;controls | Authority: Official / high-trust source | Refresh: Quarterly

Jurisdiction
United States
Issuer
NIST
Effective
2020-09-23

Articles (1018)

Access Control Policy and ProceduresAccount ManagementAuthenticator ManagementEvent LoggingContinuous MonitoringIncident HandlingRisk AssessmentAuthority to Process Personally Identifiable InformationRequirements and ControlsControl Structure and OrganizationAudit Storage CapacityAudit Storage Capacity | Transfer to Alternate StorageSecurity and Privacy ControlsTrustworthiness and AssuranceAccount Management | Automated System Account ManagementAccount Management | Automated Temporary and Emergency Account ManagementAccount Management | Disable AccountsAccount Management | Automated Audit ActionsAccount Management | Inactivity LogoutAccount Management | Dynamic Privilege ManagementAccount Management | Privileged User AccountsAccount Management | Dynamic Account ManagementAccount Management | Restrictions on Use of Shared and Group AccountsAccount Management | Usage ConditionsAccount Management | Account Monitoring for Atypical UsageAccount Management | Disable Accounts for High-Risk IndividualsAccess EnforcementAccess Enforcement | Dual AuthorizationAccess Enforcement | Mandatory Access ControlAccess Enforcement | Discretionary Access ControlAccess Enforcement | Security-Relevant InformationAccess Enforcement | Role-Based Access ControlAccess Enforcement | Revocation of Access AuthorizationsAccess Enforcement | Controlled ReleaseAccess Enforcement | Audited Override of Access Control MechanismsACCESS ENFORCEMENT | RESTRICT ACCESS TO SPECIFIC INFORMATION TYPESACCESS ENFORCEMENT | ASSERT AND ENFORCE APPLICATION ACCESSACCESS ENFORCEMENT | ATTRIBUTE-BASED ACCESS CONTROLACCESS ENFORCEMENT | INDIVIDUAL ACCESSACCESS ENFORCEMENT | DISCRETIONARY AND MANDATORY ACCESS CONTROLINFORMATION FLOW ENFORCEMENTINFORMATION FLOW ENFORCEMENT | OBJECT SECURITY AND PRIVACY ATTRIBUTESInformation Flow Enforcement | Processing DomainsInformation Flow Enforcement | Dynamic Information Flow ControlInformation Flow Enforcement | Flow Control of Encrypted InformationInformation Flow Enforcement | Embedded Data TypesInformation Flow Enforcement | MetadataInformation Flow Enforcement | One-Way Flow MechanismsInformation Flow Enforcement | Security and Privacy Policy FiltersInformation Flow Enforcement | Human ReviewsInformation Flow Enforcement | Enable and Disable Security or Privacy Policy FiltersInformation Flow Enforcement | Configuration of Security or Privacy Policy FiltersInformation Flow Enforcement | Data Type IdentifiersInformation Flow Enforcement | Decomposition into Policy-Relevant SubcomponentsInformation Flow Enforcement | Security or Privacy Policy Filter ConstraintsInformation Flow Enforcement | Detection of Unsanctioned InformationInformation Flow Enforcement | Domain AuthenticationInformation Flow Enforcement | Validation of MetadataInformation Flow Enforcement | Approved SolutionsInformation Flow Enforcement | Physical or Logical Separation of Information FlowsInformation Flow Enforcement | Access OnlyInformation Flow Enforcement | Modify Non-Releasable InformationInformation Flow Enforcement | Internal Normalized FormatInformation Flow Enforcement | Data SanitizationInformation Flow Enforcement | Audit Filtering ActionsInformation Flow Enforcement | Redundant/Independent Filtering MechanismsInformation Flow Enforcement | Linear Filter PipelinesInformation Flow Enforcement | Filter Orchestration EnginesInformation Flow Enforcement | Filter Mechanisms Using Multiple ProcessesInformation Flow Enforcement | Failed Content Transfer PreventionInformation Flow Enforcement | Process Requirements for Information TransferSeparation of DutiesLeast PrivilegeLeast Privilege | Authorize Access to Security FunctionsLeast Privilege | Non-Privileged Access for Nonsecurity FunctionsLeast Privilege | Network Access to Privileged CommandsLeast Privilege | Separate Processing DomainsLeast Privilege | Privileged AccountsLeast Privilege | Privileged Access by Non-Organizational UsersLeast Privilege | Review of User PrivilegesLeast Privilege | Privilege Levels for Code ExecutionLeast Privilege | Log Use of Privileged FunctionsLeast Privilege | Prohibit Non-Privileged Users from Executing Privileged FunctionsUnsuccessful Logon AttemptsUnsuccessful Logon Attempts | Purge or Wipe Mobile DeviceUnsuccessful Logon Attempts | Biometric Attempt LimitingUnsuccessful Logon Attempts | Use of Alternate Authentication FactorSystem Use NotificationUnsuccessful Logon Attempts | Use of Alternate Authentication FactorPrevious Logon NotificationPrevious Logon Notification | Unsuccessful LogonsPrevious Logon Notification | Successful and Unsuccessful LogonsPrevious Logon Notification | Notification of Account ChangesPrevious Logon Notification | Additional Logon InformationConcurrent Session ControlDevice LockDevice Lock | Pattern-Hiding DisplaysSession TerminationSession Termination | User-Initiated LogoutsSession Termination | Termination MessageSession Termination | Timeout Warning MessageSession Termination | User-Initiated LogoutsSession Termination | Termination MessageSession Termination | Timeout Warning MessagePermitted Actions Without Identification or AuthenticationSecurity and Privacy AttributesSecurity and Privacy Attributes | Dynamic Attribute AssociationSecurity and Privacy Attributes | Attribute Value Changes by Authorized IndividualsSecurity and Privacy Attributes | Maintenance of Attribute Associations by SystemAssociation of Attributes by Authorized IndividualsAttribute Displays on Objects to Be OutputMaintenance of Attribute AssociationConsistent Attribute InterpretationAssociation Techniques and TechnologiesAttribute Reassignment — Regrading MechanismsAttribute Configuration by Authorized IndividualsRemote AccessRemote Access | Monitoring and ControlRemote Access | Protection of Confidentiality and Integrity Using EncryptionRemote Access | Managed Access Control PointsRemote Access | Privileged Commands and AccessRemote Access | Protection of Mechanism InformationRemote Access | Disconnect or Disable AccessRemote Access | Authenticate Remote CommandsWireless AccessWireless Access | Authentication and EncryptionWireless Access | Disable Wireless NetworkingWireless Access | Restrict Configurations by UsersWireless Access | Antennas and Transmission Power LevelsAccess Control for Mobile DevicesAccess Control for Mobile Devices | Restrictions for Classified InformationAccess Control for Mobile Devices | Full Device or Container-Based EncryptionUse of External SystemsUse of External Systems | Limits on Authorized UseUse of External Systems | Portable Storage Devices — Restricted UseUse of External Systems | Non-Organizationally Owned Systems — Restricted UseUse of External Systems | Network Accessible Storage Devices — Prohibited UseUse of External Systems | Portable Storage Devices — Prohibited UseInformation SharingInformation Sharing | Automated Decision SupportInformation Sharing | Information Search and RetrievalPublicly Accessible ContentData Mining ProtectionAccess Control DecisionsAccess Control Decisions | Transmit Access Authorization InformationAccess Control Decisions | No User or Process IdentityReference MonitorPolicy and ProceduresLiteracy Training and AwarenessLiteracy Training and Awareness | Practical ExercisesLiteracy Training and Awareness | Insider ThreatLiteracy Training and Awareness | Social Engineering and MiningLiteracy Training and Awareness | Suspicious Communications and Anomalous System BehaviorLiteracy Training and Awareness | Advanced Persistent ThreatLiteracy Training and Awareness | Cyber Threat EnvironmentRole-Based TrainingRole-Based Training | Environmental ControlsRole-Based Training | Physical Security ControlsRole-Based Training | Practical ExercisesRole-Based Training | Processing Personally Identifiable InformationTraining RecordsTraining FeedbackAudit and Accountability Policy and ProceduresContent of Audit RecordsContent of Audit Records | Additional Audit InformationContent of Audit Records | Limit Personally Identifiable Information ElementsResponse to Audit Logging Process FailuresResponse to Audit Logging Process Failures | Storage Capacity WarningResponse to Audit Logging Process Failures | Real-Time AlertsResponse to Audit Logging Process Failures | Configurable Traffic Volume ThresholdsResponse to Audit Logging Process Failures | Shutdown on FailureResponse to Audit Logging Process Failures | Alternate Audit Logging CapabilityAudit Record Review, Analysis, and ReportingAudit Record Review, Analysis, and Reporting | Automated Process IntegrationAudit Record Review, Analysis, and Reporting | Correlate Audit Record RepositoriesAudit Record Review, Analysis, and Reporting | Central Review and AnalysisAudit Record Review, Analysis, and Reporting | Integrated Analysis of Audit RecordsAudit Record Review, Analysis, and Reporting | Correlation with Physical MonitoringAudit Record Review, Analysis, and Reporting | Permitted ActionsAudit Record Review, Analysis, and Reporting | Full Text Analysis of Privileged CommandsAudit Record Review, Analysis, and Reporting | Correlation with Information from Nontechnical SourcesAudit Record Reduction and Report GenerationAudit Record Reduction and Report Generation | Automatic ProcessingTime StampsProtection of Audit InformationProtection of Audit Information | Hardware Write-Once MediaProtection of Audit Information | Store on Separate Physical Systems or ComponentsProtection of Audit Information | Cryptographic ProtectionProtection of Audit Information | Access by Subset of Privileged UsersProtection of Audit Information | Dual AuthorizationProtection of Audit Information | Read-Only AccessProtection of Audit Information | Store on Component with Different Operating SystemNon-RepudiationNon-Repudiation | Association of IdentitiesNon-Repudiation | Validate Binding of Information Producer IdentityNon-Repudiation | Chain of CustodyNon-Repudiation | Validate Binding of Information Reviewer IdentityAudit Record RetentionAudit Record Retention | Long-Term Retrieval CapabilityAudit Record GenerationAudit Record Generation | System-Wide and Time-Correlated Audit TrailAudit Record Generation | Standardized FormatsAudit Record Generation | Changes by Authorized IndividualsAudit Record Generation | Query Parameter Audits of Personally Identifiable InformationMonitoring for Information DisclosureMonitoring for Information Disclosure | Use of Automated ToolsMonitoring for Information Disclosure | Review of Monitored SitesMonitoring for Information Disclosure | Unauthorized Replication of InformationSession AuditSession Audit | System Start-UpSession Audit | Remote Viewing and ListeningCross-Organizational Audit LoggingCross-Organizational Audit Logging | Identity PreservationCross-Organizational Audit Logging | Sharing of Audit InformationCross-Organizational Auditing | DisassociabilityPolicy and ProceduresControl AssessmentsControl Assessments | Independent AssessorsControl Assessments | Specialized AssessmentsControl Assessments | Leveraging Results from External OrganizationsInformation ExchangeInformation Exchange | Transfer AuthorizationsInformation Exchange | Transitive Information ExchangesPlan of Action and MilestonesPlan of Action and Milestones | Automation Support for Accuracy and CurrencyAuthorizationAuthorization | Joint Authorization — Intra-OrganizationAuthorization | Joint Authorization — Inter-OrganizationContinuous Monitoring | Independent AssessmentContinuous Monitoring | Trend AnalysesContinuous Monitoring | Risk MonitoringContinuous Monitoring | Consistency AnalysisContinuous Monitoring | Automation Support for MonitoringPenetration TestingPenetration Testing | Independent Penetration Testing Agent or TeamPenetration Testing | Red Team ExercisesPenetration Testing | Facility Penetration TestingInternal System ConnectionsInternal System Connections | Compliance ChecksPolicy and ProceduresBaseline ConfigurationBaseline Configuration | Automation Support for Accuracy and CurrencyBaseline Configuration | Retention of Previous ConfigurationsBaseline Configuration | Development and Test EnvironmentsBaseline Configuration | Configure Systems and Components for High-Risk AreasConfiguration Change ControlConfiguration Change Control | Automated Documentation, Notification, and Prohibition of ChangesConfiguration Change Control | Testing, Validation, and Documentation of ChangesConfiguration Change Control | Automated Change ImplementationConfiguration Change Control | Security and Privacy RepresentativesConfiguration Change Control | Automated Security ResponseConfiguration Change Control | Cryptography ManagementConfiguration Change Control | Review System ChangesConfiguration Change Control | Prevent or Restrict Configuration ChangesImpact AnalysesImpact Analyses | Separate Test EnvironmentsImpact Analyses | Verification of ControlsAccess Restrictions for ChangeAccess Restrictions for Change | Automated Access Enforcement and Audit RecordsAccess Restrictions for Change | Dual AuthorizationAccess Restrictions for Change | Privilege Limitation for Production and OperationAccess Restrictions for Change | Limit Library PrivilegesConfiguration SettingsConfiguration Settings | Automated Management, Application, and VerificationConfiguration Settings | Respond to Unauthorized ChangesLeast FunctionalityLeast Functionality | Periodic ReviewLeast Functionality | Prevent Program ExecutionLeast Functionality | Registration ComplianceLeast Functionality | Unauthorized Software — Deny-by-ExceptionLeast Functionality | Authorized Software — Allow-by-ExceptionLeast Functionality | Confined Environments with Limited PrivilegesLeast Functionality | Code Execution in Protected EnvironmentsLeast Functionality | Binary or Machine Executable CodeLeast Functionality | Prohibiting the Use of Unauthorized HardwareSYSTEM COMPONENT INVENTORYSYSTEM COMPONENT INVENTORY | UPDATES DURING INSTALLATION AND REMOVALSYSTEM COMPONENT INVENTORY | AUTOMATED MAINTENANCESYSTEM COMPONENT INVENTORY | AUTOMATED UNAUTHORIZED COMPONENT DETECTIONSYSTEM COMPONENT INVENTORY | ACCOUNTABILITY INFORMATIONSYSTEM COMPONENT INVENTORY | ASSESSED CONFIGURATIONS AND APPROVED DEVIATIONSSYSTEM COMPONENT INVENTORY | CENTRALIZED REPOSITORYSYSTEM COMPONENT INVENTORY | AUTOMATED LOCATION TRACKINGSYSTEM COMPONENT INVENTORY | ASSIGNMENT OF COMPONENTS TO SYSTEMSConfiguration Management PlanConfiguration Management Plan | Assignment of ResponsibilitySoftware Usage RestrictionsSoftware Usage Restrictions | Open-Source SoftwareUser-Installed SoftwareUser-Installed Software | Software Installation with Privileged StatusUser-Installed Software | Automated Enforcement and MonitoringInformation LocationInformation Location | Automated Tools to Support Information LocationData Action MappingSigned ComponentsPolicy and ProceduresContingency PlanContingency Plan – Communicate ChangesContingency Plan – Incorporate Lessons LearnedContingency Plan – Protect PlanContingency Plan | Coordinate With Related PlansContingency Plan | Capacity PlanningContingency Plan | Resume Mission and Business FunctionsContingency Plan | Continue Mission and Business FunctionsContingency Plan | Alternate Processing and Storage SitesContingency Plan | Coordinate With External Service ProvidersContingency Plan | Identify Critical AssetsContingency TrainingContingency Training | Simulated EventsContingency Training | Mechanisms Used in Training EnvironmentsContingency Plan TestingContingency Plan Testing | Coordinate With Related PlansContingency Plan Testing | Alternate Processing SiteContingency Plan Testing | Automated TestingContingency Plan Testing | Full Recovery and ReconstitutionContingency Plan Testing | Self-ChallengeAlternate Storage SiteAlternate Storage Site | Separation From Primary SiteAlternate Storage Site | Recovery Time and Recovery Point ObjectivesAlternate Storage Site | AccessibilityAlternate Processing SiteAlternate Processing Site | Separation from Primary SiteAlternate Processing Site | AccessibilityAlternate Processing Site | Priority of ServiceAlternate Processing Site | Preparation for UseAlternate Processing Site | Inability to Return to Primary SiteTelecommunications ServicesTelecommunications Services | Priority of Service ProvisionsTelecommunications Services | Single Points of FailureTelecommunications Services | Separation of Primary and Alternate ProvidersTelecommunications Services | Provider Contingency PlanTelecommunications Services | Alternate Telecommunication Service TestingSystem BackupSystem Backup | Testing for Reliability and IntegritySystem Backup | Test Restoration Using SamplingSystem Backup | Separate Storage for Critical InformationSystem Backup | Transfer to Alternate Storage SiteSystem Backup | Redundant Secondary SystemSystem Backup | Dual Authorization for Deletion or DestructionSystem Backup | Cryptographic ProtectionSystem Recovery and ReconstitutionSystem Recovery and Reconstitution | Transaction RecoverySystem Recovery and Reconstitution | Restore Within Time PeriodSystem Recovery and Reconstitution | Component ProtectionAlternate Communications ProtocolsSafe ModeAlternative Security MechanismsPolicy and ProceduresIdentification and Authentication (Organizational Users)Multi-Factor Authentication to Privileged AccountsMulti-Factor Authentication to Non-Privileged AccountsIndividual Authentication with Group AuthenticationAccess to Accounts — Separate DeviceAccess to Accounts — Replay ResistantSingle Sign-OnAcceptance of PIV CredentialsIdentification and Authentication (Organizational Users) | Out-of-Band AuthenticationDevice Identification and AuthenticationDevice Identification and Authentication | Cryptographic Bidirectional AuthenticationDevice Identification and Authentication | Dynamic Address AllocationDevice Identification and Authentication | Device AttestationIdentifier ManagementIdentifier Management | Prohibit Account Identifiers as Public IdentifiersIdentifier Management | Identify User StatusIdentifier Management | Dynamic ManagementIdentifier Management | Cross-Organization ManagementIdentifier Management | Pairwise Pseudonymous IdentifiersIdentifier Management | Attribute Maintenance and ProtectionAuthenticator Management | Password-Based AuthenticationAuthenticator Management | Public Key-Based AuthenticationAuthenticator Management | Change Authenticators Prior to DeliveryAuthenticator Management | Protection of AuthenticatorsAuthenticator Management | No Embedded Unencrypted Static AuthenticatorsAuthenticator Management | Multiple System AccountsAuthenticator Management | Federated Credential ManagementAuthenticator Management | Dynamic Credential BindingAuthenticator Management | Biometric Authentication PerformanceAuthenticator Management | Expiration of Cached AuthenticatorsAuthenticator Management | Managing Content of PKI Trust StoresAuthenticator Management | GSA-Approved Products and ServicesAuthenticator Management | In-Person or Trusted External Party Authenticator IssuanceAuthenticator Management | Presentation Attack Detection for Biometric AuthenticatorsAuthenticator Management | Password ManagersAuthentication FeedbackCryptographic Module AuthenticationIdentification and Authentication (Non-Organizational Users)Identification and Authentication (Non-Organizational Users) | Acceptance of PIV Credentials from Other AgenciesIdentification and Authentication (Non-Organizational Users) | Acceptance of External AuthenticatorsIdentification and Authentication (Non-Organizational Users) | Use of Defined ProfilesIdentification and Authentication (Non-Organizational Users) | Acceptance of PIV-I CredentialsIdentification and Authentication (Non-Organizational Users) | DisassociabilityService Identification and AuthenticationAdaptive AuthenticationRe-AuthenticationIdentity ProofingIdentity Proofing | Supervisor AuthorizationIdentity Proofing | Identity EvidenceIdentity Proofing | Identity Evidence Validation and VerificationIdentity Proofing | In-Person Validation and VerificationIdentity Proofing | Address ConfirmationIdentity Proofing | Accept Externally-Proofed IdentitiesPolicy and ProceduresIncident Response TrainingIncident Response Training | Simulated EventsIncident Response Training | Automated Training EnvironmentsIncident Response Training | BreachIncident Response TestingIncident Response Testing | Automated TestingIncident Response Testing | Coordination with Related PlansIncident Response Testing | Continuous ImprovementIncident Handling | Automated Incident Handling ProcessesIncident Handling | Dynamic ReconfigurationIncident Handling | Continuity of OperationsIncident Handling | Information CorrelationIncident Handling | Automatic Disabling of SystemIncident Handling | Insider ThreatsIncident Handling | Insider Threats — Intra-Organization CoordinationIncident Handling | Correlation with External OrganizationsIncident Handling | Dynamic Response CapabilityIncident Handling | Supply Chain CoordinationIncident Handling | Integrated Incident Response TeamIncident Handling | Malicious Code and Forensic AnalysisIncident Handling | Behavior AnalysisIncident Handling | Security Operations CenterIncident Handling | Public Relations and Reputation RepairIncident MonitoringIncident Monitoring | Automated Tracking, Data Collection, and AnalysisIncident ReportingIncident Reporting | Automated ReportingIncident Reporting | Vulnerabilities Related to IncidentsIncident Reporting | Supply Chain CoordinationIncident Response AssistanceIncident Response Assistance | Automation Support for Availability of Information and SupportIncident Response Assistance | Coordination with External ProvidersIncident Response PlanIncident Response Plan | BreachesInformation Spillage ResponseInformation Spillage Response | TrainingInformation Spillage Response | Post-Spill OperationsInformation Spillage Response | Exposure to Unauthorized PersonnelMaintenance Policy and ProceduresControlled MaintenanceControlled Maintenance | Automated Maintenance ActivitiesMaintenance ToolsMaintenance Tools | Inspect ToolsMaintenance Tools | Inspect MediaMaintenance Tools | Prevent Unauthorized RemovalMaintenance Tools | Restricted Tool UseMaintenance Tools | Execution with PrivilegeMaintenance Tools | Software Updates and PatchesNonlocal MaintenanceNonlocal Maintenance | Logging and ReviewNonlocal Maintenance | Comparable Security and SanitizationNonlocal Maintenance | Authentication and Separation of Maintenance SessionsNonlocal Maintenance | Approvals and NotificationsNonlocal Maintenance | Cryptographic ProtectionNonlocal Maintenance | Disconnect VerificationMaintenance PersonnelMaintenance Personnel | Individuals Without Appropriate AccessMaintenance Personnel | Security Clearances for Classified SystemsMaintenance Personnel | Citizenship Requirements for Classified SystemsMaintenance Personnel | Foreign NationalsMaintenance Personnel | Non-System MaintenanceTimely MaintenanceTimely Maintenance | Preventive MaintenanceTimely Maintenance | Predictive MaintenanceTimely Maintenance | Automated Support for Predictive MaintenanceField MaintenanceMedia Protection Policy and ProceduresMedia AccessMedia MarkingMedia StorageMedia Storage | Automated Restricted AccessMedia TransportMedia Transport | CustodiansMedia SanitizationMedia Sanitization | Review, Approve, Track, Document, and VerifyMedia Sanitization | Equipment TestingMedia Sanitization | Nondestructive TechniquesMedia Sanitization | Dual AuthorizationMedia Sanitization | Remote Purging or Wiping of InformationMedia UseMedia Use | Prohibit Use of Sanitization-Resistant MediaMedia DowngradingMedia Downgrading | Documentation of ProcessMedia Downgrading | Equipment TestingMedia Downgrading | Controlled Unclassified InformationMedia Downgrading | Classified InformationPolicy and ProceduresPhysical Access AuthorizationsPhysical Access Authorizations | Access by Position or RolePhysical Access Authorizations | Two Forms of IdentificationPhysical Access Authorizations | Restrict Unescorted AccessPhysical Access ControlPhysical Access Control | System AccessPhysical Access Control | Facility and SystemsPhysical Access Control | Continuous GuardsPhysical Access Control | Lockable CasingsPhysical Access Control | Tamper ProtectionPhysical Access Control | Physical BarriersPhysical Access Control | Access Control VestibulesAccess Control for TransmissionAccess Control for Output DevicesAccess Control for Output Devices | Link to Individual IdentityMonitoring Physical AccessMonitoring Physical Access | Intrusion Alarms and Surveillance EquipmentMonitoring Physical Access | Automated Intrusion Recognition and ResponsesMonitoring Physical Access | Video SurveillanceMonitoring Physical Access | Monitoring Physical Access to SystemsVisitor Access RecordsVisitor Access Records | Automated Records Maintenance and ReviewVisitor Access Records | Limit Personally Identifiable Information ElementsPower Equipment and CablingPOWER EQUIPMENT AND CABLING | REDUNDANT CABLINGPOWER EQUIPMENT AND CABLING | AUTOMATIC VOLTAGE CONTROLSEMERGENCY SHUTOFFEMERGENCY POWEREMERGENCY POWER | ALTERNATE POWER SUPPLY — MINIMAL OPERATIONAL CAPABILITYEMERGENCY POWER | ALTERNATE POWER SUPPLY — SELF-CONTAINEDEMERGENCY LIGHTINGEMERGENCY LIGHTING | ESSENTIAL MISSION AND BUSINESS FUNCTIONSFIRE PROTECTIONFIRE PROTECTION | DETECTION SYSTEMS — AUTOMATIC ACTIVATION AND NOTIFICATIONFIRE PROTECTION | SUPPRESSION SYSTEMS — AUTOMATIC ACTIVATION AND NOTIFICATIONFIRE PROTECTION | INSPECTIONSENVIRONMENTAL CONTROLSEnvironmental Controls | Automatic ControlsEnvironmental Controls | Monitoring with Alarms and NotificationsWater Damage ProtectionWater Damage Protection | Automation SupportDelivery and RemovalAlternate Work SiteLocation of System ComponentsInformation LeakageInformation Leakage | National Emissions Policies and ProceduresAsset Monitoring and TrackingElectromagnetic Pulse ProtectionComponent MarkingFacility LocationPolicy and ProceduresSystem Security and Privacy PlansRules of BehaviorRules of Behavior | Social Media and External Site/Application Usage RestrictionsConcept of OperationsSecurity and Privacy ArchitecturesSecurity and Privacy Architectures | Defense in DepthSecurity and Privacy Architectures | Supplier DiversityCentral ManagementBaseline SelectionBaseline TailoringInformation Security Program PlanInformation Security Program Leadership RoleInformation Security and Privacy ResourcesPlan of Action and Milestones ProcessSystem InventorySystem Inventory | Inventory of Personally Identifiable InformationMeasures of PerformanceEnterprise ArchitectureEnterprise Architecture | OffloadingCritical Infrastructure PlanRisk Management StrategyAuthorization ProcessMission and Business Process DefinitionInsider Threat ProgramSecurity and Privacy WorkforceTesting, Training, and MonitoringSecurity and Privacy Groups and AssociationsThreat Awareness ProgramThreat Awareness Program | Automated Means for Sharing Threat IntelligenceProtecting Controlled Unclassified Information on External SystemsPrivacy Program PlanPrivacy Program Leadership RoleDissemination of Privacy Program InformationDissemination of Privacy Program Information | Privacy Policies on Websites, Applications, and Digital ServicesAccounting of DisclosuresPersonally Identifiable Information Quality ManagementData Governance BodyData Integrity BoardMinimization of Personally Identifiable Information Used in Testing, Training, and ResearchComplaint ManagementPrivacy ReportingRisk FramingRisk Management Program Leadership RolesSupply Chain Risk Management StrategySupply Chain Risk Management Strategy | Suppliers of Critical or Mission-Essential ItemsContinuous Monitoring StrategyPurposingPolicy and ProceduresPosition Risk DesignationPersonnel ScreeningPersonnel Screening | Classified InformationPersonnel Screening | Formal IndoctrinationPersonnel Screening | Information Requiring Special Protective MeasuresPersonnel Screening | Citizenship RequirementsPersonnel TerminationPersonnel Termination | Post-Employment RequirementsPersonnel Termination | Automated ActionsPersonnel TransferAccess AgreementsAccess Agreements | Classified Information Requiring Special ProtectionAccess Agreements | Post-Employment RequirementsExternal Personnel SecurityPersonnel SanctionsPosition DescriptionsPolicy and ProceduresAuthority to Process PII | Data TaggingAuthority to Process PII | AutomationPersonally Identifiable Information Processing PurposesPII Processing Purposes | Data TaggingPII Processing Purposes | AutomationConsentCONSENT | TAILORED CONSENTCONSENT | JUST-IN-TIME CONSENTCONSENT | REVOCATIONPRIVACY NOTICEPRIVACY NOTICE | JUST-IN-TIME NOTICEPRIVACY NOTICE | PRIVACY ACT STATEMENTSSYSTEM OF RECORDS NOTICESystem of Records Notice | Routine UsesSystem of Records Notice | Exemption RulesSpecific Categories of Personally Identifiable InformationSpecific Categories of PII | Social Security NumbersSpecific Categories of PII | First Amendment InformationComputer Matching RequirementsPolicy and ProceduresSecurity CategorizationSecurity Categorization | Impact-Level PrioritizationRisk Assessment | Supply Chain Risk AssessmentRisk Assessment | Use of All-Source IntelligenceRisk Assessment | Dynamic Threat AwarenessRisk Assessment | Predictive Cyber AnalyticsVulnerability Monitoring and ScanningVulnerability Monitoring and Scanning | Update Vulnerabilities to Be ScannedVulnerability Monitoring and Scanning | Breadth and Depth of CoverageVulnerability Monitoring and Scanning | Discoverable InformationVulnerability Monitoring and Scanning | Privileged AccessVulnerability Monitoring and Scanning | Automated Trend AnalysesVulnerability Monitoring and Scanning | Review Historic Audit LogsVulnerability Monitoring and Scanning | Correlate Scanning InformationVulnerability Monitoring and Scanning | Public Disclosure ProgramTechnical Surveillance Countermeasures SurveyRisk ResponsePrivacy Impact AssessmentsCriticality AnalysisThreat HuntingPolicy and ProceduresAllocation of ResourcesSystem Development Life CycleSystem Development Life Cycle | Manage Preproduction EnvironmentSystem Development Life Cycle | Use of Live or Operational DataSystem Development Life Cycle | Technology RefreshAcquisition ProcessAcquisition Process | Functional Properties of ControlsAcquisition Process | Design and Implementation Information for ControlsAcquisition Process | Development Methods, Techniques, and PracticesAcquisition Process | System, Component, and Service ConfigurationsAcquisition Process | Use of Information Assurance ProductsAcquisition Process | NIAP-Approved Protection ProfilesAcquisition Process | Continuous Monitoring Plan for ControlsAcquisition Process | Functions, Ports, Protocols, and Services in UseAcquisition Process | Use of Approved PIV ProductsAcquisition Process | System of RecordsAcquisition Process | Data OwnershipSystem DocumentationSecurity and Privacy Engineering PrinciplesSecurity and Privacy Engineering Principles | Clear AbstractionsSecurity and Privacy Engineering Principles | Least Common MechanismSecurity and Privacy Engineering Principles | Modularity and LayeringSecurity and Privacy Engineering Principles | Partially Ordered DependenciesSecurity and Privacy Engineering Principles | Efficiently Mediated AccessSecurity and Privacy Engineering Principles | Minimized SharingSecurity and Privacy Engineering Principles | Reduced ComplexitySecurity and Privacy Engineering Principles | Secure EvolvabilitySecurity and Privacy Engineering Principles | Trusted ComponentsSecurity and Privacy Engineering Principles | Hierarchical TrustSecurity and Privacy Engineering Principles | Inverse Modification ThresholdSecurity and Privacy Engineering Principles | Hierarchical ProtectionSecurity and Privacy Engineering Principles | Minimized Security ElementsSecurity and Privacy Engineering Principles | Least PrivilegeSecurity and Privacy Engineering Principles | Predicate PermissionSecurity and Privacy Engineering Principles | Self-Reliant TrustworthinessSecurity and Privacy Engineering Principles | Secure Distributed CompositionSecurity and Privacy Engineering Principles | Trusted Communications ChannelsSecurity and Privacy Engineering Principles | Continuous ProtectionSecurity and Privacy Engineering Principles | Secure Metadata ManagementSecurity and Privacy Engineering Principles | Self-AnalysisSecurity and Privacy Engineering Principles | Accountability and TraceabilitySecurity and Privacy Engineering Principles | Secure DefaultsSecurity and Privacy Engineering Principles | Secure Failure and RecoverySecurity and Privacy Engineering Principles | Economic SecuritySecurity and Privacy Engineering Principles | Performance SecuritySecurity and Privacy Engineering Principles | Human Factored SecuritySecurity and Privacy Engineering Principles | Acceptable SecuritySecurity and Privacy Engineering Principles | Repeatable and Documented ProceduresSecurity and Privacy Engineering Principles | Procedural RigorSecurity and Privacy Engineering Principles | Secure System ModificationSecurity and Privacy Engineering Principles | Sufficient DocumentationSecurity and Privacy Engineering Principles | MinimizationExternal System ServicesExternal System Services | Risk Assessments and Organizational ApprovalsExternal System Services | Identification of Functions, Ports, Protocols, and ServicesExternal System Services | Establish and Maintain Trust Relationship with ProvidersExternal System Services | Consistent Interests of Consumers and ProvidersExternal System Services | Processing, Storage, and Service LocationExternal System Services | Organization-Controlled Cryptographic KeysExternal System Services | Organization-Controlled Integrity CheckingExternal System Services | Processing and Storage Location — U.S. JurisdictionDeveloper Configuration ManagementDeveloper Configuration Management | Software and Firmware Integrity VerificationDeveloper Configuration Management | Alternative Configuration Management ProcessesDeveloper Configuration Management | Hardware Integrity VerificationDeveloper Configuration Management | Trusted GenerationDeveloper Configuration Management | Mapping Integrity for Version ControlDeveloper Configuration Management | Trusted DistributionDeveloper Configuration Management | Security and Privacy RepresentativesDeveloper Testing and EvaluationDeveloper Testing and Evaluation | Static Code AnalysisDeveloper Testing and Evaluation | Threat Modeling and Vulnerability AnalysesDeveloper Testing and Evaluation | Independent Verification of Assessment Plans and EvidenceDeveloper Testing and Evaluation | Manual Code ReviewsDeveloper Testing and Evaluation | Penetration TestingDeveloper Testing and Evaluation | Attack Surface ReviewsDeveloper Testing and Evaluation | Verify Scope of Testing and EvaluationDeveloper Testing and Evaluation | Dynamic Code AnalysisDeveloper Testing and Evaluation | Interactive Application Security TestingDevelopment Process, Standards, and ToolsDevelopment Process, Standards, and Tools | Quality MetricsDevelopment Process, Standards, and Tools | Security and Privacy Tracking ToolsDevelopment Process, Standards, and Tools | Criticality AnalysisDevelopment Process, Standards, and Tools | Attack Surface ReductionDevelopment Process, Standards, and Tools | Continuous ImprovementDevelopment Process, Standards, and Tools | Automated Vulnerability AnalysisDevelopment Process, Standards, and Tools | Reuse of Threat and Vulnerability InformationDevelopment Process, Standards, and Tools | Incident Response PlanDevelopment Process, Standards, and Tools | Archive System or ComponentDevelopment Process, Standards, and Tools | Minimize Personally Identifiable InformationDeveloper-Provided TrainingDeveloper Security and Privacy Architecture and DesignDeveloper Security and Privacy Architecture and Design | Formal Policy ModelDeveloper Security and Privacy Architecture and Design | Security-Relevant ComponentsDeveloper Security and Privacy Architecture and Design | Formal CorrespondenceDeveloper Security and Privacy Architecture and Design | Informal CorrespondenceDeveloper Security and Privacy Architecture and Design | Conceptually Simple DesignDeveloper Security and Privacy Architecture and Design | Structure for TestingDeveloper Security and Privacy Architecture and Design | Structure for Least PrivilegeDeveloper Security and Privacy Architecture and Design | OrchestrationDeveloper Security and Privacy Architecture and Design | Design DiversityCustomized Development of Critical ComponentsDeveloper ScreeningUnsupported System ComponentsSpecializationPolicy and ProceduresSeparation of System and User FunctionalitySeparation of System and User Functionality | Interfaces for Non-Privileged UsersSeparation of System and User Functionality | DisassociabilitySecurity Function IsolationSecurity Function Isolation | Hardware SeparationSecurity Function Isolation | Access and Flow Control FunctionsSecurity Function Isolation | Minimize Nonsecurity FunctionalitySecurity Function Isolation | Module Coupling and CohesivenessSecurity Function Isolation | Layered StructuresInformation in Shared System ResourcesInformation in Shared System Resources | Multilevel or Periods ProcessingDenial-of-Service ProtectionDenial-of-Service Protection | Restrict Ability to Attack Other SystemsDenial-of-Service Protection | Capacity, Bandwidth, and RedundancyDenial-of-Service Protection | Detection and MonitoringResource AvailabilityBoundary ProtectionBoundary Protection | Access PointsBoundary Protection | External Telecommunications ServicesBoundary Protection | Deny by Default — Allow by ExceptionBoundary Protection | Split Tunneling for Remote DevicesBoundary Protection | Route Traffic to Authenticated Proxy ServersBoundary Protection | Restrict Threatening Outgoing Communications TrafficBoundary Protection | Prevent ExfiltrationBoundary Protection | Restrict Incoming Communications TrafficBoundary Protection | Host-Based ProtectionBoundary Protection | Isolation of Security Tools, Mechanisms, and Support ComponentsBoundary Protection | Protect Against Unauthorized Physical ConnectionsBoundary Protection | Networked Privileged AccessesBoundary Protection | Prevent Discovery of System ComponentsBoundary Protection | Automated Enforcement of Protocol FormatsBoundary Protection | Fail SecureBoundary Protection | Block Communication from Non-Organizationally Configured HostsBoundary Protection | Dynamic Isolation and SegregationBoundary Protection | Isolation of System ComponentsBoundary Protection | Separate Subnets for Connecting to Different Security DomainsBoundary Protection | Disable Sender Feedback on Protocol Validation FailureBoundary Protection | Personally Identifiable InformationBoundary Protection | Unclassified National Security System ConnectionsBoundary Protection | Classified National Security System ConnectionsBoundary Protection | Unclassified Non-National Security System ConnectionsBoundary Protection | Connections to Public NetworksBoundary Protection | Separate Subnets to Isolate FunctionsTransmission Confidentiality and IntegrityTransmission Confidentiality and Integrity | Cryptographic ProtectionTransmission Confidentiality and Integrity | Pre- and Post-Transmission HandlingTransmission Confidentiality and Integrity | Cryptographic Protection for Message ExternalsTransmission Confidentiality and Integrity | Conceal or Randomize CommunicationsTransmission Confidentiality and Integrity | Protected Distribution SystemNetwork DisconnectTrusted PathTrusted Path | Irrefutable Communications PathCryptographic Key Establishment and ManagementCryptographic Key Establishment and Management | AvailabilityCryptographic Key Establishment and Management | Symmetric KeysCryptographic Key Establishment and Management | Asymmetric KeysCryptographic Key Establishment and Management | Physical Control of KeysCryptographic ProtectionCollaborative Computing Devices and ApplicationsCollaborative Computing Devices | Physical or Logical DisconnectCollaborative Computing Devices | Disabling and Removal in Secure Work AreasCollaborative Computing Devices | Explicitly Indicate Current ParticipantsTransmission of Security and Privacy AttributesTransmission of Security and Privacy Attributes | Integrity VerificationTransmission of Security and Privacy Attributes | Anti-Spoofing MechanismsTransmission of Security and Privacy Attributes | Cryptographic BindingPublic Key Infrastructure CertificatesMobile CodeMobile Code | Identify Unacceptable Code and Take Corrective ActionsMobile Code | Acquisition, Development, and UseMobile Code | Prevent Downloading and ExecutionMobile Code | Prevent Automatic ExecutionMobile Code | Allow Execution Only in Confined EnvironmentsSecure Name/Address Resolution Service (Authoritative Source)Secure Name/Address Resolution Service (Authoritative Source) | Data Origin and IntegritySecure Name/Address Resolution Service (Recursive or Caching Resolver)Architecture and Provisioning for Name/Address Resolution ServiceSession AuthenticitySession Authenticity | Invalidate Session Identifiers at LogoutSession Authenticity | Unique System-Generated Session IdentifiersSession Authenticity | Allowed Certificate AuthoritiesFail in Known StateThin NodesDecoysPlatform-Independent ApplicationsProtection of Information at RestProtection of Information at Rest | Cryptographic ProtectionProtection of Information at Rest | Offline StorageProtection of Information at Rest | Cryptographic KeysHeterogeneityHeterogeneity | Virtualization TechniquesConcealment and MisdirectionConcealment and Misdirection | RandomnessConcealment and Misdirection | Change Processing and Storage LocationsConcealment and Misdirection | Misleading InformationConcealment and Misdirection | Concealment of System ComponentsCovert Channel AnalysisCovert Channel Analysis | Test Covert Channels for ExploitabilityCovert Channel Analysis | Maximum BandwidthCovert Channel Analysis | Measure Bandwidth in Operational EnvironmentsSystem PartitioningSystem Partitioning | Separate Physical Domains for Privileged FunctionsNon-Modifiable Executable ProgramsNon-Modifiable Executable Programs | No Writable StorageNon-Modifiable Executable Programs | Integrity Protection on Read-Only MediaExternal Malicious Code IdentificationDistributed Processing and StorageDistributed Processing and Storage | Polling TechniquesDistributed Processing and Storage | SynchronizationOut-of-Band ChannelsOut-of-Band Channels | Ensure Delivery and TransmissionOperations SecurityProcess IsolationProcess Isolation | Hardware SeparationProcess Isolation | Separate Execution Domain per ThreadWireless Link ProtectionWireless Link Protection | Electromagnetic InterferenceWireless Link Protection | Reduce Detection PotentialWireless Link Protection | Imitative or Manipulative Communications DeceptionWireless Link Protection | Signal Parameter IdentificationPort and I/O Device AccessSensor Capability and DataSensor Capability and Data | Reporting to Authorized Individuals or RolesSensor Capability and Data | Authorized UseSensor Capability and Data | Notice of CollectionSensor Capability and Data | Collection MinimizationUsage RestrictionsDetonation ChambersSystem Time SynchronizationSystem Time Synchronization | Synchronization with Authoritative Time SourceSystem Time Synchronization | Secondary Authoritative Time SourceCross Domain Policy EnforcementAlternate Communications PathsSensor RelocationSensor Relocation | Dynamic Relocation of Sensors or Monitoring CapabilitiesHardware-Enforced Separation and Policy EnforcementSoftware-Enforced Separation and Policy EnforcementHardware-Based ProtectionPolicy and ProceduresFlaw RemediationFlaw Remediation | Automated Flaw Remediation StatusFlaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective ActionsFlaw Remediation | Automated Patch Management ToolsFlaw Remediation | Automatic Software and Firmware UpdatesFlaw Remediation | Removal of Previous Versions of Software and FirmwareMalicious Code ProtectionMalicious Code Protection | Updates Only by Privileged UsersMalicious Code Protection | Testing and VerificationMalicious Code Protection | Detect Unauthorized CommandsMalicious Code Protection | Malicious Code AnalysisSystem MonitoringSystem Monitoring | System-Wide Intrusion Detection SystemSystem Monitoring | Automated Tools and Mechanisms for Real-Time AnalysisSystem Monitoring | Automated Tool and Mechanism IntegrationSystem Monitoring | Inbound and Outbound Communications TrafficSystem Monitoring | System-Generated AlertsSystem Monitoring | Automated Response to Suspicious EventsSystem Monitoring | Testing of Monitoring Tools and MechanismsSystem Monitoring | Visibility of Encrypted CommunicationsSystem Monitoring | Analyze Communications Traffic AnomaliesSystem Monitoring | Automated Organization-Generated AlertsSystem Monitoring | Analyze Traffic and Event PatternsSystem Monitoring | Wireless Intrusion DetectionSystem Monitoring | Wireless to Wireline CommunicationsSystem Monitoring | Correlate Monitoring InformationSystem Monitoring | Integrated Situational AwarenessSystem Monitoring | Analyze Traffic and Covert ExfiltrationSystem Monitoring | Risk for IndividualsSystem Monitoring | Privileged UsersSystem Monitoring | Probationary PeriodsSystem Monitoring | Unauthorized Network ServicesSystem Monitoring | Host-Based DevicesSystem Monitoring | Indicators of CompromiseSystem Monitoring | Optimize Network Traffic AnalysisSecurity Alerts, Advisories, and DirectivesSecurity Alerts, Advisories, and Directives | Automated Alerts and AdvisoriesSecurity and Privacy Function VerificationSecurity and Privacy Function Verification | Automation Support for Distributed TestingSecurity and Privacy Function Verification | Report Verification ResultsSoftware, Firmware, and Information IntegritySoftware, Firmware, and Information Integrity | Integrity ChecksSoftware, Firmware, and Information Integrity | Automated Notifications of Integrity ViolationsSoftware, Firmware, and Information Integrity | Centrally Managed Integrity ToolsSoftware, Firmware, and Information Integrity | Automated Response to Integrity ViolationsSoftware, Firmware, and Information Integrity | Cryptographic ProtectionSoftware, Firmware, and Information Integrity | Integration of Detection and ResponseSoftware, Firmware, and Information Integrity | Auditing Capability for Significant EventsSoftware, Firmware, and Information Integrity | Verify Boot ProcessSoftware, Firmware, and Information Integrity | Protection of Boot FirmwareSoftware, Firmware, and Information Integrity | Integrity VerificationSoftware, Firmware, and Information Integrity | Code AuthenticationSoftware, Firmware, and Information Integrity | Time Limit on Process Execution Without SupervisionSoftware, Firmware, and Information Integrity | Runtime Application Self-ProtectionSpam ProtectionSpam Protection | Automatic UpdatesSpam Protection | Continuous Learning CapabilityInformation Input ValidationInformation Input Validation | Manual Override CapabilityInformation Input Validation | Review and Resolve ErrorsInformation Input Validation | Predictable BehaviorInformation Input Validation | Timing InteractionsInformation Input Validation | Restrict Inputs to Trusted Sources and Approved FormatsInformation Input Validation | Injection PreventionError HandlingInformation Management and RetentionInformation Management and Retention | Limit Personally Identifiable Information ElementsInformation Management and Retention | Minimize Personally Identifiable Information in Testing, Training, and ResearchInformation Management and Retention | Information DisposalPredictable Failure PreventionPredictable Failure Prevention | Transferring Component ResponsibilitiesPredictable Failure Prevention | Manual Transfer Between ComponentsPredictable Failure Prevention | Standby Component Installation and NotificationPredictable Failure Prevention | Failover CapabilityNon-PersistenceNon-Persistence | Refresh from Trusted SourcesNon-Persistence | Non-Persistent InformationNon-Persistence | Non-Persistent ConnectivityInformation Output FilteringMemory ProtectionFail-Safe ProceduresPersonally Identifiable Information Quality OperationsPersonally Identifiable Information Quality Operations | Automation SupportPII Quality Operations | Data TagsPII Quality Operations | CollectionPII Quality Operations | Individual RequestsPII Quality Operations | Notice of Correction or DeletionDe-IdentificationDe-Identification | CollectionDe-Identification | ArchivingDe-Identification | ReleaseDe-Identification | Removal, Masking, Encryption, Hashing, or Replacement of Direct IdentifiersDe-Identification | Statistical Disclosure ControlDE-IDENTIFICATION | DIFFERENTIAL PRIVACYDE-IDENTIFICATION | VALIDATED ALGORITHMS AND SOFTWAREDE-IDENTIFICATION | MOTIVATED INTRUDERTAINTINGINFORMATION REFRESHINFORMATION DIVERSITYINFORMATION FRAGMENTATIONPOLICY AND PROCEDURESSupply Chain Risk Management PlanSupply Chain Risk Management Plan | Establish SCRM TeamSupply Chain Controls and ProcessesSupply Chain Controls and Processes | Diverse Supply BaseSupply Chain Controls and Processes | Limitation of HarmSupply Chain Controls and Processes | Sub-Tier Flow DownProvenanceProvenance | IdentityProvenance | Track and TraceProvenance | Validate as Genuine and Not AlteredProvenance | Supply Chain Integrity — PedigreeAcquisition Strategies, Tools, and MethodsAcquisition Strategies, Tools, and Methods | Adequate SupplyAcquisition Strategies, Tools, and Methods | Assessments Prior to Selection, Acceptance, Modification, or UpdateSupplier Assessments and ReviewsSupplier Assessments and Reviews | Testing and AnalysisSupply Chain Operations SecurityNotification AgreementsTamper Resistance and DetectionTamper Resistance and Detection | Multiple Stages of System Development Life CycleInspection of Systems or ComponentsComponent AuthenticityComponent Authenticity | Anti-Counterfeit TrainingComponent Authenticity | Configuration Control for Component Service and RepairComponent Authenticity | Anti-Counterfeit ScanningComponent Disposal